Securing your open-source software supply chain with Tidelift catalogs
Summary
The Solarwinds security disaster, which will be causing trouble from now until the end of 2021, happened because the company fouled up its software supply chain. With catalogs, part of the Tidelift Subscription, companies get a comprehensive approach to curating, tracking, and managing their open-source components. Heres how: • None A paved path: Organizations can accelerate development and reduce security and licensing-related risk by defining and curating catalogs of known-good, proactively maintained open source components. • None For legal: Get a single place to define, review, and enforce license policies and get indemnification to protect against licensing-related risk. It might just be what we need until the day comes when we have what David A Wheeler, the Linux Foundations director of Open Source Supply Chain Security, has called Verified reproducible builds.